Visualização de leitura

Ransomware Attacks Surge 30% in 2026 as Qilin and INC Ransom Intensify Operations

Qilin

Ransomware attacks surged 30% in the first half of 2026 compared to the same period in 2025, with Qilin and INC Ransom emerging as two of the most prolific and dangerous operators in a crowded criminal ecosystem. Healthcare continues to be the top targeted industry, with 27 incidents in January 2026 alone, a figure that reflects both the sector's operational sensitivity and the premium value of health records on darknet markets.

Qilin: The Dominant Force

Qilin — also known as Agenda — is a ransomware group that entered 2026 accelerating, not slowing down. By early 2026, Qilin had already posted 55 confirmed victims, placing it ahead of its own 2025 pace. By June 2026, tracking data, Qilin had accumulated 168 confirmed victims in the healthcare sector alone, behind only manufacturing (291) and business services (245) in overall victim count. Qilin operates as a Ransomware-as-a-Service (RaaS) platform, recruiting affiliates who conduct attacks using Qilin's ransomware builder and infrastructure in exchange for a percentage of ransom proceeds. This model allows the core group to expand operational throughput without directly executing every attack. The group's double extortion model — encrypting victim data while simultaneously exfiltrating it and threatening public release on their leak site — has proven effective at pressuring victims into paying ransom demands even when robust backups exist. Public exposure of sensitive patient records creates regulatory, legal, and reputational pressure that many healthcare organisations find more immediately damaging than operational downtime. A notable recent case involves Covenant Health, which suffered a Qilin ransomware breach that exposed 478,188 patient records. The Covenant Health incident highlights Qilin's willingness to attack hospitals and health systems regardless of the direct patient safety implications.

INC Ransom: Targeting Critical Sectors

INC Ransom is another highly active operator that was among the top ransomware groups by victim count in January 2026, with 47 known attacks that month. The group targets organisations across multiple sectors, including healthcare, legal services, and public administration. INC Ransom gained significant attention in 2025 for its attack on NHS Scotland, which exposed 3 terabytes of patient data. The group continues to operate aggressively in 2026, targeting entities including healthcare practices, municipal agencies, and regional service providers. Recent INC Ransom victims include healthcare organisations such as Lymphedema Therapy Specialists, Inc. (February 2026, affecting 378 Texas patients) and various municipal and public sector entities, including Champaign-Urbana Public Health District.

The 2026 Ransomware Landscape

Beyond Qilin and INC Ransom, the broader 2026 ransomware ecosystem is characterised by:
  • AI-assisted operations: Multiple ransomware groups are now using AI tools to accelerate phishing campaign creation, target research, and initial access operations, reducing the operational cost of launching attacks.
  • Healthcare as a premium target: Patient records sell for up to 10 times as much as financial records on darknet markets, making it a persistently attractive target. Operational disruption of healthcare services also creates patient-safety leverage that can pressure organisations to make faster payment decisions.
  • The Play and SafePay operators were also confirmed in recent June 2026 attack disclosures, targeting organisations including Clínica Maitenes and various regional businesses.

Why It Matters

The 30% year-over-year increase in ransomware incidents confirms that neither law enforcement action nor improved defensive capabilities has materially reduced the operational tempo of ransomware criminal enterprises. The professionalisation of RaaS platforms, combined with AI-assisted tooling and shortened attack timelines, is creating conditions in which even well-defended organisations face materially elevated risk. For healthcare specifically, the combination of operational sensitivity, high data value, and historically underfunded security programmes creates a structural vulnerability that the industry has not yet resolved despite years of high-profile attacks.

Vulnerability Exploitation Overtakes Stolen Credentials in AI-Driven Cyberattacks

Vulnerability Exploitation

Vulnerability exploitation has officially become the leading cause of cybersecurity breaches for the first time in nearly two decades, according to the latest Data Breach Investigations Report (DBIR) released by Verizon. The findings highlight how artificial intelligence is rapidly reshaping the threat landscape, enabling attackers to weaponize software flaws faster than security teams can respond. The 19th edition of the DBIR revealed that 31% of all recorded breaches now begin with vulnerability exploitation, surpassing stolen credentials as the most common attack entry point. Researchers warned that AI-driven automation is dramatically reducing the time between vulnerability disclosure and active exploitation, shrinking defensive response windows from months to just hours. The report paints a broader picture of an evolving cybersecurity environment where AI-powered attacks, mobile-focused social engineering, shadow AI usage, and supply chain compromises are all expanding organizational risk.

Vulnerability Exploitation Surpasses Stolen Credentials

For years, stolen usernames and passwords remained the primary method used by cybercriminals to breach corporate systems. However, the latest DBIR findings show a major shift in attacker behavior. Researchers found that threat actors are increasingly prioritizing vulnerability exploitation because AI tools can quickly identify weak systems, automate reconnaissance, and accelerate exploit development. According to the report, attackers are now moving much faster after vulnerabilities become public. Organizations that previously had weeks or months to deploy security patches are now facing exploitation attempts within hours of disclosure. Security experts said this trend is creating significant pressure on security operations teams already struggling to manage patching priorities across complex environments. Daniel Lawson, Senior Vice President of Global Solutions at Verizon Business, said the growing speed of cyberattacks reinforces the importance of strong cybersecurity fundamentals. “While the velocity of cyber threats driven by AI and faster vulnerability exploitation is increasing, the foundational principles of security and strong risk management remain the most effective defense,” Lawson said.

AI Reshaping the Cyber Threat Landscape

The report repeatedly emphasized the growing influence of artificial intelligence on cybercrime operations. Researchers noted that AI is not only helping defenders identify vulnerabilities more efficiently, but also allowing attackers to automate exploitation at unprecedented scale and speed. The DBIR warned that AI-assisted attack workflows are creating what researchers described as a “capacity crisis” for many security teams. Organizations are being forced to process increasing numbers of vulnerabilities while facing shorter remediation timelines. The report recommended that enterprises:
  • Strengthen patch management programs
  • Reduce overall attack surface exposure
  • Integrate AI into secure-by-design frameworks
  • Expand defense-in-depth strategies
  • Improve visibility into internet-facing assets
Researchers also highlighted rapid growth in AI bot activity across the internet. According to the report, AI bot crawler traffic is increasing by 21% month over month, while human-driven traffic growth remains almost flat at just 0.3%.

Mobile Social Engineering Attacks Rising

Beyond vulnerability exploitation, the DBIR identified major changes in social engineering tactics. As users become more cautious about traditional phishing emails, attackers are increasingly shifting toward mobile-based scams involving text messages and voice calls. The report found that conversational and interactive mobile attacks now achieve success rates roughly 40% higher than traditional email phishing campaigns. Researchers said attackers are leveraging:
  • Fake SMS messages
  • Voice phishing calls
  • Messaging app impersonation
  • Mobile account verification scams
Cybersecurity analysts warned that mobile devices continue to represent a major blind spot for many organizations because security monitoring on smartphones often remains less mature than on corporate desktops and servers.

Shadow AI Creates New Data Leakage Risks

Another major concern highlighted in the DBIR involves the rapid rise of “shadow AI” usage inside organizations. The term refers to employees using unapproved artificial intelligence tools without formal oversight from security or compliance teams. According to Verizon’s findings, frequent use of AI platforms by employees surged from 15% to 45% within a single year. Researchers said shadow AI has now become the third most common cause of non-malicious data leakage incidents. Security experts warned that employees may unknowingly expose:
  • Confidential corporate data
  • Customer information
  • Source code
  • Internal business documents
  • Sensitive communications
The report stressed that organizations need clearer governance policies around AI usage as adoption continues accelerating across workplaces.

Supply Chain Breaches Continue to Grow

The DBIR also documented a significant rise in third-party and supply chain compromises. Researchers found that breaches involving external vendors increased by 60% compared to previous reporting periods. Third-party involvement now accounts for 48% of all recorded breaches. As organizations rely more heavily on cloud providers, software vendors, and outsourced services, attackers are increasingly targeting weaker links within interconnected supply chains. The report concluded that the cybersecurity industry is entering a period where resilience, rapid response capabilities, and basic security hygiene remain critical despite rapid advances in AI-powered attack techniques. While artificial intelligence is changing the speed and scale of cyber threats, researchers stressed that organizations must continue focusing on foundational cybersecurity practices to defend against the growing wave of vulnerability exploitation and AI-driven attacks.

AI Cyberattacks Are Escalating Across the Americas. This Webinar Explains Why

Americas cyber threat landscape

The Americas cyber threat landscape saw a significant rise in AI-powered cyberattacks, ransomware campaigns, and critical infrastructure targeting during the first quarter of 2026, reflecting how rapidly cyber threats are evolving across the region. Security researchers observed that threat actors increasingly used generative AI to automate phishing campaigns, create convincing deepfakes, and accelerate exploitation techniques. At the same time, ransomware groups, hacktivists, and nation-state actors intensified attacks against organizations operating in healthcare, manufacturing, utilities, energy, and government sectors across North and Latin America. To help cybersecurity professionals better understand these evolving risks, Cyble will host a live webinar on May 28, 2026, focused on the key cyber threats, adversary tactics, and emerging attack trends shaping the Americas cyber threat landscape in Q1 2026. Americas cyber threat landscape

AI-Powered Cyber Threats Continue to Grow

One of the most notable developments during Q1 2026 was the increasing use of artificial intelligence by cybercriminals and advanced threat groups. Threat actors are now leveraging generative AI to produce highly targeted phishing emails, fake identities, deepfake content, and automated social engineering campaigns at scale. Security analysts warn that these AI-driven techniques are making attacks more difficult to identify and increasing the success rate of phishing and credential theft operations. Researchers also observed that attackers are using AI to accelerate reconnaissance and exploitation activities, enabling cybercriminals to move faster and target larger numbers of victims simultaneously. As AI-powered attacks become more sophisticated, organizations are facing growing pressure to strengthen detection capabilities and improve incident response readiness.

Critical Infrastructure Remains a Primary Target

The Americas cyber threat landscape also highlighted the continued targeting of critical infrastructure sectors during Q1 2026. Healthcare providers, energy operators, utilities, manufacturing organizations, and public sector institutions experienced persistent cyber threats from ransomware operators, hacktivist groups, and nation-state actors. Security researchers noted increasing concerns around operational technology environments and attacks designed to disrupt essential services. Supply chain vulnerabilities and third-party risks also remained major challenges for organizations responsible for maintaining critical infrastructure. Experts believe these attacks are no longer solely focused on financial extortion. Many campaigns are increasingly linked to geopolitical tensions, intelligence gathering, and disruption-focused objectives targeting national infrastructure and strategic industries. Cybersecurity professionals looking for deeper insights into infrastructure threats and AI-driven attack trends can register for the upcoming webinar hosted by Cyble.
Register Here

Nation-State Cyber Operations Intensify

Threat intelligence findings from Q1 2026 also revealed growing activity from nation-state groups associated with China, Russia, Iran, and North Korea. These groups continued targeting organizations across the Americas through espionage campaigns, vulnerability exploitation, credential theft, and malware deployment. Researchers observed that government entities, infrastructure operators, and large enterprises remained among the primary targets of these advanced cyber operations. Security experts warn that geopolitical developments continue to influence cyber activity, increasing the need for organizations to monitor emerging risks and strengthen resilience against sophisticated attacks.

Ransomware and Dark Web Activity Continue

Despite the growing attention around AI-driven threats, ransomware remained one of the most disruptive elements of the Americas cyber threat landscape in Q1 2026. Threat actors continued targeting organizations across multiple industries using double extortion tactics, data theft, and operational disruption strategies. Researchers also identified ongoing activity across dark web marketplaces and underground forums supporting cybercriminal operations through the sale of stolen credentials, access data, and attack tools. Hacktivist groups also remained active during the quarter, particularly in campaigns linked to political and regional conflicts. Security teams are increasingly prioritizing real-time threat intelligence and attack surface visibility to identify risks earlier and respond more effectively to emerging threats. The upcoming webinar will feature insights from Kaustubh Medhe, Head of Research & Intelligence at Cyble, Brian Osterman, Senior Solutions Engineer for the US region, and moderator Mihir Bagwe. The session will explore ransomware trends, AI-powered attacks, nation-state cyber operations, and practical recommendations for strengthening cyber resilience in 2026. Registered attendees will also receive a complimentary copy of the Americas Threat Landscape Report – Q1 2026. Webinar Details Date: Wednesday, May 28, 2026 Time: 1:00 PM ET Duration: 45 Minutes

Registration Link: Click Here

IOCTA 2026 Report Warns of Rising AI-Driven Cybercrime and Dark Web Threats

IOCTA 2026 report

The IOCTA 2026 report released by Europol offers a detailed look at how cybercrime is evolving across Europe, with criminals increasingly using artificial intelligence, encryption, and cryptocurrencies to scale their operations. The latest edition of the Internet Organised Crime Threat Assessment outlines key trends shaping the threat landscape and calls for stronger coordination among law enforcement agencies. According to the IOCTA 2026 report, cybercrime is becoming more complex and interconnected, driven by rapid technological advancements. The findings highlight how criminals are adapting quickly, making it harder for authorities to detect, track, and disrupt their activities.

IOCTA 2026 Report Maps Evolving Cyber Threat Landscape

The IOCTA 2026 report serves as a roadmap for understanding emerging cyber threats, covering areas such as online fraud, ransomware attacks, and child exploitation networks. Edvardas Šileris, Head of the European Cybercrime Centre at Europol, emphasized that the report is intended to help law enforcement agencies respond effectively to these evolving risks. He noted that as cybercriminals continue to exploit new technologies, strengthening capabilities and improving collaboration will be essential to protect citizens and critical infrastructure.

Dark Web Fragmentation and Cryptocurrencies Fuel Crime

A key finding in the IOCTA 2026 report is the continued role of the dark web as a central hub for cybercriminal activity. Despite ongoing crackdowns, marketplaces and forums remain active, with criminals frequently shifting platforms to avoid detection. The report highlights how fragmentation and specialization across these platforms make investigations more difficult. Encrypted messaging services and anonymized networks are increasingly connecting surface and dark web environments, reducing the visibility of criminal operations. Cryptocurrencies also play a significant role, according to the IOCTA 2026 report. Privacy-focused coins and offshore exchanges are widely used to launder ransomware payments, making financial tracking more challenging. The report also points to a growing trend of younger individuals becoming involved in cryptocurrency-related activities, sometimes without understanding the legal risks.

AI-Driven Fraud Expands Across Europe

The IOCTA 2026 report identifies artificial intelligence as a major driver of online fraud. Cybercriminals are using generative AI tools to create highly targeted phishing campaigns and social engineering attacks. These tools allow attackers to:
  • Personalize fraudulent messages at scale
  • Mimic legitimate communication styles
  • Automate large-scale scam operations
The report also highlights the use of caller ID spoofing and SIM farms, which enable attackers to send thousands of messages or calls simultaneously. This combination of AI and automation is increasing both the reach and success rate of fraud campaigns.

Ransomware and Data Extortion Remain Key Threats

Ransomware continues to be a dominant threat, as outlined in the IOCTA 2026 report. A large number of active ransomware groups were observed throughout 2025, with many adopting data extortion tactics. Instead of relying solely on encryption, attackers are increasingly threatening to release stolen data to pressure victims into paying. This shift has made cyberattacks more damaging, particularly for public institutions and large organizations. The report also notes growing links between state-sponsored actors and criminal groups, with some cybercriminals acting as proxies in broader geopolitical strategies. Emerging hacking coalitions are adding another layer of complexity to the threat landscape.

Rise in Online Child Exploitation and Criminal Networks

The IOCTA 2026 report highlights a concerning increase in online child sexual exploitation cases. The financial trade of child abuse material is growing, and the use of synthetic content is creating new challenges for investigators. Encrypted messaging platforms are widely used by offenders, making it harder for authorities to monitor and intervene. The report also points to the emergence of organized online communities that engage in multiple forms of criminal activity. These networks combine cybercrime with violent offenses, creating a complex and dangerous ecosystem that extends beyond digital spaces.

Need for Stronger Law Enforcement Collaboration

The findings of the IOCTA 2026 report reinforce the need for improved coordination between governments, law enforcement agencies, and industry stakeholders. As cyber threats become more advanced, isolated efforts are no longer sufficient. The report provides actionable insights and recommendations aimed at strengthening investigative capabilities and improving response strategies. It also stresses the importance of innovation in tackling new forms of cybercrime.

March 2026 Cyber Threat Landscape Fueled by Ransomware, Breaches, and Access Markets

2026 threat landscape

The 2026 threat landscape continued to intensify in March, with ransomware attacks, expanding data breach activity, and a growing underground market for compromised access shaping the global cybersecurity environment. According to analysis from CRIL (Cyble Research & Intelligence Labs), organizations worldwide faced a highly active and coordinated threat ecosystem throughout the month.  CRIL’s findings point to a cybercriminal landscape driven by financial extortion, credential theft, and operational disruption. Attackers consistently targeted industries that rely heavily on uptime or store large volumes of sensitive data, reinforcing the urgency for stronger defensive strategies. 

Ransomware Attacks Dominate the 2026 Threat Landscape 

Top five ransomware actors (Data Source: Cyble Blaze AI) One of the most defining aspects of the March 2026 threat landscape was the scale of ransomware attacks. CRIL recorded 702 ransomware incidents globally, underscoring the continued dominance of ransomware as a primary attack vector.  Among the most active threat groups were Qilin, Akira, The Gentlemen, Dragonforce, and INC Ransom. Collectively, these actors were responsible for over 56% of all observed ransomware activity, reflecting their operational maturity and extensive affiliate networks.  Industries most affected by ransomware attacks included: 
  • Construction  
  • Professional Services  
  • Manufacturing  
  • Healthcare  
  • Energy & Utilities  
Attackers frequently employed double-extortion tactics, combining data theft with system disruption to increase pressure on victims. Geographically, the United States remained the primary target, influenced in part by ongoing geopolitical tensions, including those involving Iran. 

Rise of Access Brokers in the CRIL Threat Analysis 

Another notable trend in the 2026 threat landscape, as identified by CRIL, was the continued growth of the compromised access market. During March, 20 separate incidents involving the sale of unauthorized network access were tracked across cybercrime forums.  The most targeted sectors for access sales were: 
  • Professional Services (25%)  
  • Retail (20%)  
  • IT & ITES  
  • Manufacturing  
A small group of threat actors, vexin, holyduxy, and algoyim, dominated this space, accounting for more than 55% of observed listings. These access brokers play a critical upstream role, enabling ransomware attacks, espionage campaigns, and financial fraud operations. 

Data Breaches and Leak Markets Stay Active 

CRIL also documented 54 significant data breach and leak incidents in March, further highlighting the scale of data exposure risks in the current 2026 threat landscape.  The most targeted sectors for data breaches included: 
  • Government & Law Enforcement  
  • Retail  
  • Technology  
Several incidents stood out: 
  • A threat actor known as “nightly” claimed to have stolen over 5TB of data from Hospitality Holdings, including biometric data, CCTV footage, and financial records. 
  • Another actor, XP95, advertised 3.8TB of allegedly stolen South African government data for sale.  
  • A separate breach exposed more than 95,000 travel-related records, including passport and payment information.  

Exploitation of Critical Vulnerabilities Accelerates 

The 2026 threat landscape also saw increased exploitation of critical vulnerabilities, particularly those listed in CISA’s Known Exploited Vulnerabilities (KEV) catalog.  Key vulnerabilities targeted included: 
  • CVE-2026-20131 (Cisco Secure Firewall Management Center)  
  • CVE-2025-53521 (F5 BIG-IP APM)  
  • CVE-2026-20963 (Microsoft SharePoint Server)  
  • CVE-2026-33017 (Langflow AI)  
  • CVE-2021-22681 (Rockwell Automation ICS 
CRIL observed attackers exploiting both newly disclosed zero-day vulnerabilities and older, unpatched flaws. This trend reflects persistent gaps in patch management and exposure mitigation across organizations. 

Emerging Threat Developments in March 2026 

Beyond ransomware attacks and data breaches, CRIL identified several strategic developments shaping the 2026 threat landscape: 
  • AI-Driven Attacks: Threat actors reportedly leveraged an open-source framework called CyberStrikeAI to target Fortinet FortiGate devices across 55 countries, compromising more than 600 systems. 
  • Supply Chain RisksNorth Korean-linked actors were associated with 26 malicious npm packages distributing remote access trojans (RATs) via infrastructure hosted on Pastebin and Vercel. 
  • Geopolitical Cyber Activity: Iran-linked cyber operations are expected to increase, with potential ransomware attacks and hacktivist campaigns targeting organizations in the Middle East. 
❌